Key Takeaways The 2026 LaPorte Report defines Embedded Runtime Security (ERS) as a distinct discipline for protecting deployed embedded software at runtime. ERS makes exploit attempts fail at execution, rather than relying solely on vulnerability discovery and...
The European Union’s Cyber Resilience Act (CRA) began requiring manufacturers of connected products to report actively exploited vulnerabilities on a tight schedule in September 2026. Medical device makers have lived with similar post-market expectations from...
The world has changed, and software security has to change with it. Artificial intelligence is changing the risk profile of software by accelerating vulnerability discovery and exploit development. Geopolitical tensions are rising, putting more critical systems into...
In late July, a coordinated cyberattack hit the operational technology (OT) at more than 30 community water systems in Minnesota, the first state to confirm what has since grown into a much larger campaign. Cyberattacks on water and wastewater systems have now been...
On July 27, 2026, the European Commission published its most substantial guidance yet on applying the EU Cyber Resilience Act (CRA). The guidance helps manufacturers, developers, and businesses of all sizes by working through questions that have caused the most...